[curriculum-eval] side-quest-17-07-repo-poisoning.md: cognitive_load — 23 security concepts introduced before any worked example
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 72/100
- Tipo de issue
- Documentación
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- github, markdown, yaml
- Área
- content
Línea de trabajo
Lee workshop/side-quest-17-07-repo-poisoning.md, centrándote en “The Attack”, “Why This Matters” y “How AW Defends Against It”. Añade el ejemplo solicitado de YAML vulnerable y el ejercicio “Spot the risk”; después, divide las defensas en ejemplos con etiquetas y listas de comprobación breves. La tarea estará completa cuando la lección incluya más comprobaciones prácticas sin añadir prosa sustancial; verifica que el archivo revisado se lea de forma coherente.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.95 / 10.0 (corpus mean: 6.09)
Flagged Dimensions:
| Dimension | Score | Benchmark | Delta |
|---|---|---|---|
| active_learning | 2.7 |
density ≥ 3 → 10 | -7.3 |
| cognitive_load | 5.8 |
≤800 words, ≤15 concepts → 10 | -4.2 |
Root Cause (≤ 2 sentences):
This security side quest introduces 23 new concepts (permissions scoping, contents: read/write, safe-outputs: create-pull-request, network.allowed-domains, protected-files, branch protection, CODEOWNERS, content-driven manipulation) across 1,234 words of mostly narrative/explanatory prose (the "Attack" and "Why This Matters" sections) before any hands-on application, so cognitive load is high while activity density stays low.
Evidence (quoted from the file):
"Repository poisoning is what happens when a misdirected agent with write access commits changes an attacker designed — not changes the workflow author intended." — this scenario-and-rationale narrative spans roughly 300 words across two full sections before the reader reaches any applied defensive configuration.
Learning Science Rationale:
Sweller's Cognitive Load Theory predicts that introducing many new, interdependent security concepts (permission scoping, safe-outputs, network allowlisting, protected-files, branch protection) in rapid narrative succession without intermediate worked examples overloads working memory capacity (typically 4±1 novel chunks), making it hard for learners to encode the causal chain between "why the attack works" and "which specific field stops it."
Improvement Prompt (for an agent):
Edit workshop/side-quest-17-07-repo-poisoning.md to reduce cognitive load and raise active
learning density. After "The Attack" and "Why This Matters" sections, insert a short worked
example (a 5-10 line YAML code block showing a vulnerable frontmatter snippet with
`contents: write` and no `network.allowed-domains`) immediately followed by a "Spot the risk"
checklist-style micro-exercise asking the learner to identify the dangerous field before
revealing the fix. Split the "How AW Defends Against It" section (which currently introduces
contents:read, safe-outputs:create-pull-request, network.allowed-domains, and protected-files
together) into one labeled code example per defense, each with its own 1-2 item inline
checklist, so code_blocks + checklist_items increases relative to word_count without adding
new prose.
Expected Score After Fix: 6.3-6.8 / 10.0
Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 96.9 AIC · ⌖ 19.9 AIC · ⊞ 10.4K · ◷
- expires on Oct 8, 2026, 11:43 PM UTC
- Lenguaje dominante
- JavaScript
- Estrellas
- 52
- Forks
- 26
- Merge medio
- 12 h 25 min
- PR fusionados (30 d)
- 18
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Sin guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de githubnext/gh-aw-workshop
-
feedback simulation workshop
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
githubnext/gh-aw-workshop#4370 ·
Los mantenedores suelen responder en 1 día
-
feedback simulation workshop
Dificultad 2/5 1-3 horas Aptitud para principiantes 64/100
githubnext/gh-aw-workshop#4369 ·
Los mantenedores suelen responder en 1 día
-
feedback simulation workshop
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
githubnext/gh-aw-workshop#4368 ·
Los mantenedores suelen responder en 1 día
-
documentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
githubnext/gh-aw-workshop#4366 ·
Los mantenedores suelen responder en 1 día
-
documentation
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
githubnext/gh-aw-workshop#4365 ·
Los mantenedores suelen responder en 1 día
Todos los issues de githubnext/gh-aw-workshop
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
no-human-ai/no_human#659 ·
Los mantenedores suelen responder en 1 día
-
[BUG] Multi-day events show "Ended" while still in progressPosiblemente ocupada @tarunagnihotri534 la tomó hoy. Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
data-umbrella/du-event-board#231 · 2 comentarios ·
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 78/100
-
IO.get_env on Node truncates names at embedded NULPosiblemente ocupada @Yi-111-a la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
HigherOrderCO/Bend#1449 · 1 comentario ·
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 72/100
cryptpad/documentation#162 ·